First published: Fri Mar 18 2022(Updated: )
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <6.4.0 |
Update Mattermost to version v6.4 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-1003.
The affected software for this vulnerability is Mattermost version 6.3.0 and earlier.
The severity level of this vulnerability is medium.
The CWE ID of this vulnerability is CWE-269 and CWE-268.
You can find more information about this vulnerability on the Mattermost website.
To fix this vulnerability, you should update your Mattermost installation to version 6.4.0 or later.